Oracle Database 19c Unified Audit Trail
JSON rows from a defined 22-column projection of the Oracle Database 19c UNIFIED_AUDIT_TRAIL view, as a connector polling that view would deliver them, for SIEM content that correlates database logons, sensitive reads and privilege changes. Not Oracle syslog output or a native Oracle JSON export. About 8,600 rows a day: application connection pools write around the clock, five analysts and four administrators follow a UTC working day. Recurring episodes show a guessed administrator password followed by a payroll read and a payroll role grant to an analyst.
Quick Start
uv tool install eventum-generator
git clone https://github.com/eventum-generator/content-packs.git
cd content-packs
eventum generate \
--path generators/database-oracle-unified-audit/generator.yml \
--id oracle-audit \
--live-mode trueEvent Types
| Event ID | Description | Frequency | Category |
|---|---|---|---|
| SELECT | Reporting, HR and payroll table reads (APP_DATA_AUDIT) | 74.96% of rows | database access |
| UPDATE | HR employee phone updates (APP_DATA_AUDIT) | 11.13% of rows | database change |
| LOGON | Successful session start (APP_SESSION_AUDIT) | 6.65% of rows | authentication |
| LOGOFF | Session end (APP_SESSION_AUDIT) | 6.53% of rows | authentication |
| LOGON 1017 | Invalid username/password, ORA-01017 (ORA_LOGON_FAILURES) | 0.27% of rows | authentication |
| REVOKE | Administrator revokes an application role (ORA_ACCOUNT_MGMT) | 0.23% of rows | iam |
| GRANT | Administrator grants an application role (ORA_ACCOUNT_MGMT) | 0.23% of rows | iam |
Realism Features
- About 8,600 rows a day with ±3% day-to-day variation: about 465 rows an hour 07:00-19:00 UTC and about 250 at night. Application connection pools write about 90% of the rows around the clock, with more work between 07:00 and 19:00 UTC. Analysts and administrators open about 170 sessions a day, about 16 times as often 08:00-18:00 UTC as at night and about five times as often at 07-08 and 18-19. The hour curves repeat every day, so weekends look like weekdays.
- Every session is a LOGON that opens a new SESSIONID, statements and a LOGOFF. 41 pools (APP_READ, BI_APP, HR_APP, ETL_APP, PAYROLL_APP) each log on about ten times a day and run a median 12 statements minutes apart. Five analysts and four administrators each use one to three usual hosts, including the shared jump01.corp.example, and have at most two sessions open at once. Analysts read REPORTING.DAILY_SALES, HR.EMPLOYEES and FINANCE.PAYROLL and update HR.EMPLOYEES by job (median 4-6 statements, 45 s apart); administrators run short sessions (median 2 statements, 30 s apart) that read the three tables, update HR.EMPLOYEES and manage roles. Rates are workload assumptions, not measured Oracle frequencies.
- About 1% of pool logons fail with ORA-01017 (a stale saved password) and are retried within seconds. A person's first logon attempt fails in 5% (analysts) or 7% (administrators) of sessions; the retry follows a median 20 s later, fails again with probability 0.35, and after a failure the person gives up in 15% of cases. About 9% of people's logon attempts and 3.5% of all logon attempts fail, about 20 a day; no account reaches ten consecutive failures, where the DEFAULT profile would lock it.
- Administrators grant PAYROLL_READ, APP_REPORTER, HR_VIEW and SALES_READ to the five analysts, about 20-25 grants a day, about half of them PAYROLL_READ, only to an analyst who does not hold the role. 60% of grants are revoked by the same administrator and host in a follow-up session a median 30 minutes later; the rest are held for a median 90 minutes and revoked in the next role cleanup, so a late grant is revoked the next morning. About 70% of revokes come from the granting administrator and host; the median time from grant to revoke is about 45 minutes.
- In both modes the episode administrators at their usual hosts log on about 25-35 times a day, fail a logon two to four times a day, sometimes three or more times in a row before succeeding, read payroll about 15-40 times a day and grant PAYROLL_READ two to five times a day, revoking it in follow-up sessions of the same shape as the episode restoration. A session opened after three or more failures of its account and host within 30 minutes that reads payroll grants a role other than PAYROLL_READ. With episodes, failed logons are about 15-20% more frequent and runs of three or more failures followed by a successful logon occur about two to three times a day instead of one to two.
- Assumed audit configuration: ORA_LOGON_FAILURES, ORA_ACCOUNT_MGMT and example custom policies APP_SESSION_AUDIT and APP_DATA_AUDIT over HR.EMPLOYEES (Oracle sample schema) and the synthetic REPORTING.DAILY_SALES and FINANCE.PAYROLL. All grants are authorized, so the episode is suspicious only by the order and timing of its events.
- The modeled connector writes NUMBER as JSON numbers, NULL as null and both TIMESTAMP(6) columns as YYYY-MM-DD HH24:MI:SS.FF6 in a UTC database, so local and UTC timestamps are equal. SQL_BINDS is null (literals only), failed logons have null CURRENT_USER (unconfirmed), SESSIONID steps do not emulate Oracle allocation and STATEMENT_ID gaps stand for unaudited statements. One instance; rows of one session, including password retries, are at least a few seconds apart, where real clients can retry within a second. Byte-level row fidelity and live nullability are unverified against a version-matched 19c export of this projection.
Sample Output
{
"ACTION_NAME": "GRANT",
"AUDIT_TYPE": "Standard",
"CLIENT_PROGRAM_NAME": "sqlplus@wkst-091.corp.example (TNS V1-V3)",
"CURRENT_USER": "FINANCE_DBA",
"DBID": 3459081234,
"DBUSERNAME": "FINANCE_DBA",
"ENTRY_ID": 4,
"EVENT_TIMESTAMP": "2026-09-20 17:37:02.534192",
"EVENT_TIMESTAMP_UTC": "2026-09-20 17:37:02.534192",
"INSTANCE_ID": 1,
"OBJECT_NAME": null,
"OBJECT_SCHEMA": null,
"OS_USERNAME": "mnovak",
"RETURN_CODE": 0,
"ROLE": "PAYROLL_READ",
"SESSIONID": 3006292300,
"SQL_BINDS": null,
"SQL_TEXT": "GRANT PAYROLL_READ TO HR_ANALYST",
"STATEMENT_ID": 6,
"TARGET_USER": "HR_ANALYST",
"UNIFIED_AUDIT_POLICIES": "ORA_ACCOUNT_MGMT",
"USERHOST": "wkst-091.corp.example"
}Parameters
| Parameter | Default | Description |
|---|---|---|
| anomaly_mode | true | Generate the recurring failed-logon, payroll-read and grant chain; false emits ordinary background only |
| anomaly_interval_hours | 24 | Hours between episode due times, counted from the previous actual start; 6 to 8,760 |
| database_id | 3459081234 | Synthetic numeric DBID |
Related Generators
Microsoft SQL Server Audit
SQL Server Audit via Windows Event ID 33205 — login/logout lifecycle, DML queries (SELECT/INSERT/UPDATE/DELETE), stored procedure execution, schema changes (CREATE/ALTER/DROP), permission management (GRANT/DENY/REVOKE), role membership, backups, DBCC commands, and password changes.
MySQL Audit
MySQL Enterprise Audit Plugin events (ECS-compatible JSON) covering all four audit classes — connection, general, table_access, and audit. Generates connect/disconnect lifecycle, DML queries (SELECT/INSERT/UPDATE/DELETE), table access tracking, DDL schema changes, GRANT/REVOKE privileges, admin commands, query errors, and failed authentication attempts with realistic query statistics.
PostgreSQL Audit Logs
PostgreSQL with pgAudit — SELECT/INSERT/UPDATE/DELETE queries with parameterized statements, connection lifecycle, authentication failures, DDL operations, role management (GRANT/REVOKE), and database errors (deadlocks, constraint violations).